On August 24, 2026, Germany's consumer protection agency (Verbraucherzentrale) issued a warning about a new wave of phishing emails impersonating Postbank. The messages claim that the recipient's BestSign function — Postbank's TAN and transaction-approval procedure for online banking — urgently needs to be "renewed," giving victims a deadline of just 24 hours and threatening that the account will otherwise be blocked. This is far from an isolated case. Just weeks earlier, starting August 8, nearly identical emails circulated in the name of the Sparkassen-Finanzgruppe, announcing a fake "S-pushTAN security update." There, the scam went a step further: anyone who clicked the link and entered their details on the fake website received a follow-up phone call that appeared — thanks to caller-ID spoofing — to come from Sparkasse's genuine, publicly known phone number.
Having tracked these fraud waves for years as a financial journalist, I can say the pattern itself is not new — but the combination of a digital lure followed by a telephone follow-up makes this particular August wave especially dangerous. It shows just how professionally organized these criminal operations have become, and why a healthy baseline of suspicion toward any unexpected message from "your bank" is no longer paranoia — it is simply necessary.
Why a 24-hour deadline is always a red flag
The psychological trick behind the Postbank scam is as simple as it is effective: manufactured time pressure. Anyone who believes they have only 24 hours before their account gets blocked stops thinking clearly — and clicks. This is exactly where legitimate banks fundamentally differ from fraudsters. Postbank, Sparkasse, Deutsche Bank, Comdirect, or any other licensed bank in Germany will never impose a multi-hour ultimatum by email to "renew" a TAN procedure. Security-relevant changes to approval methods like BestSign or pushTAN are handled through the official banking app, through the securely logged-in online banking area, or via postal notice — never through a link in an email with a ticking clock.
A second telltale sign is the threatening tone itself. Account suspension, loss of access, a supposed "final notice" — these phrases are designed to maximize emotion rather than convey information. Genuine bank communication is, as a rule, sober, specific, and points customers toward official channels rather than issuing ultimatums. Anyone receiving such an email should ask themselves one simple question: would my bank really pressure me like this? The answer is almost always no.
A call from the "real" number is no proof of authenticity
Far more sophisticated — and therefore more worrying — is the variant observed around the Sparkassen-Finanzgruppe. After clicking the phishing link and entering data on a fake website, victims received a phone call during which their display showed Sparkasse's actual, well-known service number. Technically, this is known as caller-ID spoofing: fraudsters manipulate the transmitted phone number so it appears trustworthy on the victim's phone, even though the call originates from somewhere else entirely. During the call, victims are pressured into reading out a TAN or confirming a "security release" — which then gives the criminals full access to the account.
The key lesson here is that in the age of spoofing, a displayed phone number is no longer a reliable indicator of authenticity — not for banks, not for government agencies, not for delivery services. The one truly safe rule is this: no bank employee will ever call you and ask you to read out a TAN, under any circumstances — not for "confirmation," not for "activation," not for a "security check." TANs exist solely to approve a transaction that you yourself initiated in the app or online banking. The moment someone on the phone asks for one, the call should end immediately.
What to do if you receive a message like this
- Never click links in the email. Instead, open your bank's official app or type in the web address you already know yourself.
- Check the sender's address carefully — even though fraudsters now build deceptively convincing look-alike domains, close inspection often reveals small discrepancies.
- Stay suspicious of phone calls, even when the number looks genuine. Hang up and call back using the number printed on your bank card or listed in your official customer portal.
- Never enter a TAN by phone or on a linked website unless you personally requested it through the app or online banking.
- Report suspicious cases — both to your bank and to the consumer protection agency's phishing radar. Doing so helps warn other customers in time.
Anyone who has already shared their data should act immediately: contact the bank right away (using the official number, never one from the suspicious email or call), block cards and access, and file a police report.
Trust is the real target
These attack waves ultimately target not just individual accounts, but trust in digital banking as a whole. That is exactly why it is worth regularly reviewing your own banking products and their security features — not only reactively, after fraud occurs. If you are already considering a switch, it's worth comparing current personal accounts that offer modern, phishing-resistant approval methods, or checking how savings accounts and fixed-term deposits protect their customers against fraud. Anyone thinking about a loan or a mortgage should also keep this in mind: legitimate providers never communicate contract changes through an urgency-driven email with a countdown.
Bottom line: The Postbank and Sparkasse cases from August 2026 are a wake-up call. Artificial deadlines, threats of account suspension, and even a seemingly trustworthy caller are no longer guarantees of authenticity. Stay calm, use only official channels, and never — under any circumstances — read out a TAN over the phone. When in doubt: hang up first, then call back yourself.